CVE-2026-98188: wifi: p54: validate curve data length in the calibration curve converters
Published Oct 6, 2026
·Updated
In the Linux kernel, the following vulnerability has been resolved:
wifi: p54: validate curve data length in the calibration curve converters
p54convertrev0() and p54convertrev1() read calibration curve data from the device-supplied EEPROM entry using channel and points-per-channel counts taken verbatim from that same entry, so an entry that declares more data than it carries drives an out-of-bounds read past the EEPROM buffer (verified with a KASAN reproducer of the conversion loop). The sibling converters p54convertoutputlimits() and p54convertdb() already validate their counts against the entry length; this path was missed.
Reject the entry when the counts do not fit in the entry data.
Affected Software
1 affected component
Linux Linux kernel
Event History
Oct 6, 2026
CVE Published
via MITRE·08:44 AM
Data Sourced
via MITRE·08:44 AM
Description
Data Sourced
via NVD·09:18 AM
Description